Impact
A flaw was identified in the fetch_article function of the article-scraper-mcp package, which allows an attacker to manipulate the URL argument and trigger a server‑side request forgery. The vulnerability can cause the target server to make unintended outbound HTTP requests to arbitrary hosts, potentially exposing sensitive data or allowing further malicious actions. The weakness is classified as CWE-918 and does not directly provide arbitrary code execution, but it enables remote entities to reach internal systems or cause data leakage.
Affected Systems
The affected product is dmitriiweb article‑scraper‑mcp version 1.0.0. No other versions or additional products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the precise likelihood of exploitation in the wild is unknown, but the exploit is published and can be executed from a remote location. The vulnerability is not listed in the CISA KEV catalog, but because the attacker can make arbitrary requests, it poses a significant risk to confidentiality and integrity of internal resources. The preferred attack vector is remote via HTTP requests to the server, and the vendor has not yet provided a patch or workaround.
OpenCVE Enrichment